Ngân hàng đề — Google Professional Cloud Architect
Tìm thấy 420 câu.
You are a cloud architect working on a large-scale application that leverages various Google Cloud services, including Bigtable, Firestore, and Pub/Sub. Your development team is transitioning from a monolithic architecture to a microservices architecture, and you are tasked with implementing a testing strategy that includes the use of cloud emulators to ensure each service is properly tested in isolation before integration. Which of the following strategies would be most effective for managing this implementation using Google Cloud emulators?
-
A
Configure separate CI/CD pipelines to include stages that set up and tear down emulators for each service, ensuring isolated environment testing during development.
-
B
Only use local machine emulators for development and skip CI/CD integration, relying on developer discipline to conduct necessary tests.
-
C
Utilize the Google Cloud SDK to deploy emulators for Bigtable, Firestore, and Pub/Sub directly in the production environment for live testing.
-
D
Implement a single emulator that mimics all services (Bigtable, Firestore, and Pub/Sub) to simplify the testing process and reduce resource usage.
Xem giải thích
Đáp án
A — Cấu hình pipeline CI/CD riêng, mỗi pipeline tự dựng và tự dọn emulator
Vì sao đúng
Emulator cho Bigtable, Firestore và Pub/Sub giúp test chạy nhanh, rẻ và không đụng dữ liệu thật. Điểm quan trọng là dựng chúng trong chính pipeline và dọn sau khi xong: mỗi lần chạy có môi trường sạch, không có trạng thái sót lại từ lần trước làm test đỏ ngẫu nhiên.
Vì sao các phương án khác sai
- B. Chỉ dùng emulator ở máy cá nhân, bỏ qua CI/CD — test chỉ chạy khi ai đó nhớ chạy, và "chạy được trên máy tôi" quay lại.
- C. Dùng SDK triển khai emulator — mô tả lệch: emulator chạy cục bộ trong môi trường build, không phải thứ được triển khai lên hạ tầng.
- D. Một emulator mô phỏng cả ba dịch vụ — không tồn tại; mỗi dịch vụ có emulator riêng.
A global online retail company is designing a new cloud-native application to support its expanding business. The application must handle high traffic during flash sales, provide a seamless user experience worldwide, and ensure that data is secure and compliant with regional regulations. The development team is building the application using a microservices architecture, with services deployed in containers. The company is particularly concerned about optimizing the application design for performance, security, and scalability.
The business requirements include:
-
Global Availability: Ensure low-latency access for users worldwide.
-
Scalability: Automatically scale to handle spikes in traffic during flash sales.
-
Security: Protect customer data and ensure compliance with regional data protection laws.
-
Resilience: Minimize downtime and quickly recover from failures.
Which architectural decisions best support the application design for the global online retail company? (Choose three)
-
A
Implement a multi-region database with strong consistency guarantees using Cloud Spanner.
-
B
Use a single Cloud SQL instance for the database to reduce complexity.
-
C
Use Google Kubernetes Engine (GKE) to manage microservices in multiple regions.
-
D
Leverage Google Cloud's Secret Manager for storing and accessing sensitive configuration data.
-
E
Deploy the application in a single region with a global load balancer.
Xem giải thích
Đáp án
A, C và D — CSDL đa vùng nhất quán mạnh, GKE ở nhiều khu vực, và Secret Manager
Vì sao đúng
Ba mảnh phủ ba mối lo của một ứng dụng bán lẻ toàn cầu:
- A. CSDL đa vùng nhất quán mạnh (Cloud Spanner) — đơn hàng và tồn kho không chấp nhận đọc ra dữ liệu cũ; đây là lý do người ta chấp nhận trả giá cao cho nhất quán mạnh.
- C. GKE nhiều khu vực — chịu được lưu lượng dồn theo mùa và vẫn phục vụ khi mất một khu vực.
- D. Secret Manager — khoá API và thông tin đăng nhập được lưu tập trung, xoay vòng và kiểm toán được, thay vì nằm trong tệp cấu hình.
Vì sao các phương án khác sai
- B. Một instance Cloud SQL duy nhất — điểm hỏng duy nhất và có trần mở rộng.
- E. Triển khai một khu vực rồi dùng load balancer toàn cầu — cân bằng tải toàn cầu không cứu được khi chính khu vực đó sập.
Your company operates a large-scale data center in Frankfurt, Germany, and is expanding into Google Cloud. The goal is to integrate workloads across environments with low latency, high throughput, and secure, private connectivity. There is a requirement for SLA-backed uptime and throughput guarantees. What is the most appropriate solution?
-
A
Use Dedicated Interconnect from a colocation facility near the data center
-
B
Use Carrier Peering to establish a connection between the environments
-
C
Use Cloud VPN with dynamic routing over the public internet
-
D
Use Cloud NAT to securely bridge the two networks
Xem giải thích
Đáp án
A — Dùng Dedicated Interconnect từ một cơ sở colocation gần trung tâm dữ liệu
Vì sao đúng
Với trung tâm dữ liệu lớn cần tích hợp khối lượng công việc, yêu cầu là băng thông cao, độ trễ thấp và ổn định. Dedicated Interconnect cho đường vật lý riêng nối vào mạng Google với dung lượng 10 hoặc 100 Gbps, không đi qua Internet công cộng. Frankfurt là nơi có nhiều điểm kết nối của Google nên phương án này khả thi về mặt địa lý.
Vì sao các phương án khác sai
- B. Carrier Peering — cho truy cập dịch vụ Google qua nhà mạng, không nối vào VPC riêng của bạn, nên không dùng để tích hợp khối lượng công việc.
- C. Cloud VPN qua Internet — độ trễ và băng thông phụ thuộc Internet công cộng, không đạt mức ổn định cần thiết.
- D. Cloud NAT — cho máy không có IP công khai đi ra Internet; không phải cơ chế nối hai môi trường.
You are designing a multi-tier application where the front-end services are hosted in a Virtual Private Cloud (VPC) in region A and the back-end services are hosted in a separate VPC in region B. You need to enable communication between the front-end and back-end services while ensuring low latency and cost efficiency. Which networking approach would best meet these requirements?
-
A
Use Cloud Interconnect to link the two VPCs.
-
B
Set up VPC Peering between the two VPCs.
-
C
Use Cloud VPN to connect the two VPCs.
-
D
Set up a public IP for the back-end VPC and route traffic through the public internet.
Xem giải thích
Đáp án
B — Thiết lập VPC Peering giữa hai VPC
Vì sao đúng
Hai VPC đều nằm trong Google Cloud, chỉ khác khu vực. VPC peering nối chúng bằng đường nội bộ của Google: lưu lượng đi qua địa chỉ IP riêng, không ra Internet, độ trễ thấp và không tốn phí cổng như VPN. Thiết lập chỉ là khai hai chiều rồi khớp nhau.
Vì sao các phương án khác sai
- A. Cloud Interconnect — dành cho việc nối từ ngoài vào Google Cloud, ví dụ trung tâm dữ liệu tại chỗ; dùng cho hai VPC là sai công cụ và rất đắt.
- C. Cloud VPN — chạy được nhưng thêm cổng VPN phải vận hành, băng thông thấp hơn và tốn hơn peering.
- D. Mở IP công khai cho tầng back end — phơi tầng dữ liệu ra Internet, sai cả về bảo mật lẫn hiệu năng.
You are managing a project that consists of a single Virtual Private Cloud (VPC) and a single subnetwork located in the us-west1 region. Within this subnetwork, there is a Compute Engine instance hosting an application. Now, your development team intends to deploy a new instance within the same project, but in the europe-central2 region. They require access to the application and wish to adhere to Google's best practices. As a cloud architect, what guidance should you provide in this situation?
-
A
They should create a VPC and a subnetwork in
europe-central2region. Than, peer the 2 VPCs, and finally create a new instance in the new subnetwork and use the first instance's private address as the endpoint. -
B
They should create a VPC and a subnetwork in
europe-central2region. Than, expose the application with an internal load balancer, and finally create a new instance in the new subnetwork and use the load balancer's address as the endpoint. -
C
They should create a subnetwork in the same VPC, in
europe-central2region. Than, use Cloud VPN to connect these two subnetworks, and finally create a new instance in the new subnetwork and use the first instance's private address as the endpoint. -
D
They should create a subnetwork in the same VPC, in
europe-central2region. Than, create a new instance in the new subnetwork and use the first instance's private address as the endpoint.
Xem giải thích
Đáp án
D — Tạo subnet mới trong cùng VPC ở khu vực europe-central2
Vì sao đúng
Điểm mấu chốt là VPC của Google Cloud mang tính toàn cầu, còn subnet thì gắn với một khu vực. Vì vậy mở rộng sang khu vực mới chỉ cần thêm một subnet vào chính VPC đang có — máy ở hai khu vực tự nói chuyện được bằng IP riêng, dùng chung luật tường lửa và không cần peering hay VPN gì.
Đây là khác biệt lớn so với VPC của AWS, vốn bó trong một khu vực.
Vì sao các phương án khác sai
- A và B. Tạo VPC mới ở khu vực kia — dựng thêm một mạng rồi lại phải nối hai mạng với nhau, hoàn toàn không cần thiết.
- C — đúng phần tạo subnet trong cùng VPC nhưng phần còn lại của phương án không đạt.
A company is moving an enterprise application to the Google Cloud. This application runs on a cluster of virtual machines on private data center, and workloads are distributed by a load balancer. Select all true statements. (Choose two)
-
A
The migration team decided to use containers and the Kubernetes Engine. This migration strategy is called Remove and Replace.
-
B
The migration team decided to use containers and the Kubernetes Engine. This migration strategy is called Improve and Move.
-
C
The migration team decided not to make unnecessary changes before moving this application to the cloud. This migration strategy is called Lift and Shift.
-
D
The migration team decided to use containers and the Kubernetes Engine. This migration strategy is called Lift and Shift.
-
E
The migration team decided not to make unnecessary changes before moving this application to the cloud. This migration strategy is called Improve and Move.
Xem giải thích
Đáp án
B và C
Vì sao đúng
Câu này kiểm tra tên gọi của ba chiến lược di chuyển:
- C. Lift and Shift — chuyển gần như nguyên trạng, không sửa gì không cần thiết. Nhanh nhất, rủi ro thấp nhất, nhưng cũng không tận dụng được gì của đám mây.
- B. Improve and Move — cải tiến trong lúc chuyển, ví dụ đóng gói ứng dụng thành container rồi chạy trên Kubernetes Engine. Đây đúng là mô tả trong phương án.
Vì sao các phương án khác sai
- A. Gọi việc container hoá là Remove and Replace — sai tên: Remove and Replace nghĩa là bỏ hẳn ứng dụng cũ và thay bằng giải pháp khác, thường là dịch vụ SaaS.
- D. Gọi việc container hoá là Lift and Shift — sai, vì đóng gói lại chính là một thay đổi.
- E. Gọi việc giữ nguyên là Improve and Move — sai, vì không có cải tiến nào diễn ra.
For this question, refer to the Altostrat Media case study.
https://services.google.com/fh/files/misc/v6.1_pca_altostrat_media_case_study_english.pdf
Altostrat operates a hybrid environment where legacy on-premises systems ingest and archive large volumes of raw audio and video content. These assets are periodically transferred to Google Cloud for processing, metadata extraction, and distribution through GKE- and Cloud Run–based services. Recently, operational teams have experienced frequent ingestion failures caused by unstable network connections and manual retry processes. These failures delay downstream workflows and reduce reliability across both on-premises and cloud environments. Altostrat wants to accelerate ingestion workflows and make them more reliable, while minimizing operational overhead and preparing for future modernization. Which architecture should Altostrat implement to improve reliability and operational efficiency of hybrid ingestion workflows?
-
A
Use Storage Transfer Service with scheduled jobs and event-based triggers to move data from on-premises systems into Cloud Storage.
-
B
Implement Cloud Interconnect and move all ingestion logic into GKE using custom retry logic.
-
C
Use Cloud VPN to connect on-premises systems and rely on cron jobs to retry failed file transfers to Cloud Storage.
-
D
Deploy a custom ingestion service on Compute Engine with persistent disks to buffer content before upload.
Xem giải thích
Đáp án
A — Dùng Storage Transfer Service với lịch chạy và trình kích hoạt theo sự kiện
Vì sao đúng
Storage Transfer Service là dịch vụ được quản lý cho việc đưa dữ liệu vào Cloud Storage: chạy theo lịch hoặc theo sự kiện, tự thử lại khi lỗi, kiểm tra toàn vẹn bằng checksum, và chỉ chuyển phần thay đổi ở những lần sau. Không có máy chủ nào phải dựng cho khâu nạp dữ liệu.
Vì sao các phương án khác sai
- B. Dựng logic nạp dữ liệu trong GKE — tự viết và tự vận hành thứ đã có dịch vụ làm sẵn.
- C. Cloud VPN cộng cron — script cron phải tự lo thử lại, kiểm tra toàn vẹn và theo dõi tiến độ; đây là chỗ hay hỏng âm thầm.
- D. Dịch vụ nạp dữ liệu tự viết trên Compute Engine — cùng vấn đề, cộng thêm máy phải vá.
A machine learning team needs to use a Kubernetes Engine cluster with specific GPUs to process long running jobs that cannot be restarted. In this case, how do you recommend configuring the Kubernetes Engine cluster?
-
A
They should deploy the workload on a node pool with preemptible compute engine instances and GPUs attached.
-
B
They should deploy the workload on a node pool with non-preemptible compute engine instances and GPUs attached. Enable cluster autoscaling and set min-nodes to 1.
-
C
They should enable Vertical Pod autoscaling.
-
D
They should enable Kubernetes Engine cluster node auto-provisioning.
Xem giải thích
Đáp án
B — Triển khai lên node pool dùng máy không phải preemptible
Vì sao đúng
Điều kiện quyết định nằm ngay trong đề: công việc chạy dài và không khởi động lại được. Máy preemptible (hay Spot) có thể bị Google thu hồi bất cứ lúc nào với thông báo trước rất ngắn, nên dùng cho loại công việc này là chắc chắn mất kết quả. Node pool thường tuy đắt hơn nhưng là lựa chọn duy nhất đúng.
Vì sao các phương án khác sai
- A. Dùng node pool preemptible — rẻ nhưng vi phạm thẳng điều kiện của đề.
- C. Bật Vertical Pod Autoscaling — điều chỉnh tài nguyên cấp cho pod, và việc đó thường khởi động lại pod — đúng thứ phải tránh.
- D. Bật node auto-provisioning — giúp cụm tự tạo node pool phù hợp, nhưng không giải quyết chuyện máy bị thu hồi.
For this question, refer to the Cymbal Retail case study.
https://services.google.com/fh/files/misc/v6.1_pca_cymbal_retail_case_study_english.pdf
Cymbal wants to increase customer engagement during product discovery by introducing conversational commerce on its website and mobile app. The solution must reduce call center load, provide accurate product recommendations across a large catalog, and integrate with existing Kubernetes-based services. Cymbal also wants to avoid managing NLP infrastructure and prefers a fully managed, scalable solution that can evolve over time. Which architecture best meets Cymbal’s goals for conversational product discovery while following Google Cloud best practices?
-
A
Use Dialogflow CX integrated with Cloud Functions and BigQuery to provide conversational product search and recommendations
-
B
Build a custom chatbot running on GKE using open-source NLP libraries and directly query relational databases for product data
-
C
Extend the existing IVR system to support text-based chat and connect it directly to MySQL databases
-
D
Deploy a third-party chatbot on Compute Engine VMs and sync product data nightly using SFTP
Xem giải thích
Đáp án
A — Dùng Dialogflow CX kết hợp Cloud Functions và BigQuery
Vì sao đúng
Ba mảnh đúng vai: Dialogflow CX lo phần hiểu ngôn ngữ tự nhiên và quản lý luồng hội thoại nhiều bước — thứ mà tự viết sẽ rất tốn. Cloud Functions làm cầu nối gọi ra hệ thống nghiệp vụ khi cần tra cứu đơn hàng hay tồn kho. BigQuery cung cấp dữ liệu để trả lời và nhận lại lịch sử hội thoại để phân tích.
Vì sao các phương án khác sai
- B. Tự dựng chatbot trên GKE bằng thư viện mã nguồn mở — phải tự xây và tự nuôi phần hiểu ngôn ngữ, tốn nhất.
- C. Mở rộng hệ thống IVR hiện có — IVR dựng cho điện thoại theo kịch bản phím bấm, không phải nền tảng hội thoại.
- D. Chatbot bên thứ ba trên máy ảo, đồng bộ dữ liệu định kỳ — dữ liệu luôn cũ và thêm hạ tầng phải vận hành.
For this question, refer to the EHR Healthcare case study.
https://services.google.com/fh/files/misc/v6.1_pca_ehr_healthcare_case_study_english.pdf
EHR is interested in establishing a connection between one of its data centers and Google Cloud. However, the data center is situated in a remote location that is over 100 kilometers away from a Google-owned point of presence (POP). Budget constraints prevent them from acquiring new hardware, but an existing firewall can accommodate future throughput growth. Additionally, they provided the following information:
-
communication is required between servers in their on-premises data center and Google Kubernetes Engine (GKE) resources in the cloud
-
both on-premises servers and cloud resource are set up with private RFC 1918 IP addresses
-
the service provider has notified the customer that basic internet connectivity is provided as a best-effort service and does not come with any service level agreement (SLA)
In your role as a cloud architect, what connectivity option would you recommend?
-
A
Provision a Dedicated Interconnect connection.
-
B
Provision Carrier Peering.
-
C
Provision a Partner Interconnect connection.
-
D
Provision a new Internet connection.
Xem giải thích
Đáp án
C — Dùng Partner Interconnect
Vì sao đúng
Partner Interconnect là lựa chọn đúng khi không đặt được thiết bị ở cơ sở colocation gần điểm kết nối của Google, hoặc khi nhu cầu băng thông chưa tới mức 10 Gbps. Bạn nối qua một nhà cung cấp dịch vụ đối tác, chọn dung lượng từ 50 Mbps tới 50 Gbps, mà vẫn được đường riêng vào VPC chứ không đi qua Internet công cộng.
Vì sao các phương án khác sai
- A. Dedicated Interconnect — băng thông cao nhất nhưng đòi bạn có mặt tại cơ sở colocation và bắt đầu từ 10 Gbps; quá nặng khi nhu cầu nhỏ hơn.
- B. Carrier Peering — chỉ cho truy cập dịch vụ công khai của Google, không nối vào VPC riêng.
- D. Thêm đường Internet — không cho kết nối riêng và không có cam kết về độ trễ.